Team settings
Plan and limits, defaults, security controls, and the settings worth changing on day one.
Team settings apply to everyone and are Admin-only, including billing.
Set these on day one
Timezone and week start
Every date truncation depends on them. Changing later shifts historical charts.
Number and date format
Decimal separator, thousands separator, currency, and date order.
Sensitive field tagging
Tag personal fields before anyone builds on them — see Data handling.
Session length
Shorter sessions for teams with customer data.
Changing the timezone rewrites history
A dashboard grouped by day re-buckets every row when the timezone moves. Set it once, at the start, to where the business actually operates.
Plan and limits
| Limit | Free | Pro | Enterprise |
|---|---|---|---|
| Active sources | 5 | 20 | Negotiated |
| Datasets | 50 | 500 | Negotiated |
| Seats | 3 | 25+ | Negotiated |
| Storage | 1 GB | 100 GB | Negotiated |
| Sync frequency | Daily | 15 minutes | 1 minute |
| Audit retention | 30 days | 12 months | Unlimited |
The Overview tab’s 8 / 20 counter tracks active sources. Pausing frees a slot without losing
datasets or charts.
Defaults
| Setting | Applies to |
|---|---|
| Default refresh policy | New datasets |
| Default chart palette | New charts |
| Default project visibility | New projects — set to Private |
| Default member role | Accepted invitations |
Default new projects to Private
The alternative makes every new project team-visible, which is discovered later, usually by someone who should not have seen it.
Security
| Control | Plan | Notes |
|---|---|---|
| SAML SSO | Enterprise | Optionally enforced |
| SCIM provisioning | Enterprise | Members become read-only here |
| Two-factor authentication | All | Can be required team-wide |
| Session length | Pro+ | 1 hour to 30 days |
| IP allowlist | Enterprise | Applies to app and API |
| Link sharing | All | Can be disabled entirely |
| Embed domains | Pro+ | Origins allowed to frame embeds |
Review auto-approved domains
Link shares are approved per person by an admin, so a leaked URL grants nothing on its own — with one exception. An auto-approve domain waves through anyone with an address at that domain. Audit that list, and disable link sharing team-wide if you would rather it never be an option — see Sharing.
Agents
Settings → Agents lists local agents with version, host, and status. Update agents when the version column shows an update available — see Local agents.
Source credentials outlive their creators
A source keeps syncing after the person who connected it is removed — until the credentials behind it are disabled upstream. Move sources onto a service account as part of offboarding.
Transfer or delete
Hand over a team by promoting another member to Admin. There is no separate owner to transfer: every admin has the same rights, including billing, so handover is a promotion rather than a transfer. Demote yourself afterwards if you are stepping away — as long as one admin remains.
Delete team is Admin-only, requires typing the team name, and is irreversible after a 30-day grace period, during which the data can be restored by support.
Export the team first from Settings → Export. The export contains dataset definitions, chart and dashboard configuration, and files — not the contents of connected databases, which remain yours in the source system.